iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 certification in the UK, with the arithmetic shown

How many audit days the published rule requires for your headcount, what that tends to cost here, and why the body that audits you is barred from being the firm that gets you ready. Tell us how many people are in scope and the numbers appear on this page.

  • The audit-day table, published in full. All 22 bands of ISO/IEC 27006-1:2024 Table C.1, from 1 person to 10,700. Most sites in this market summarise it. It is the one number in your quote that is not negotiable.
  • Written for the UK. UKAS accreditation, what an accredited certificate actually is, and what happens when a customer checks. The large US platforms cannot write this page.
  • Three routes, priced side by side. Toolkit, consultant-led, or a compliance platform. A toolkit vendor leans one way and a platform vendor leans the other. We are paid the same whichever you pick.

Start with the only number that matters

The headcount inside your scope drives the audit days, and the audit days drive the fee. Everything else adjusts around it.

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
5 primary sources cited on this page. How we check what is on this site

The short version

  • Audit days are fixed by a published rule, not by your certification body’s sales team. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) gives 22 bands by headcount. A quote that does not reconcile to it needs explaining.
  • Surveillance is one third of the initial audit and recertification is two thirds — in every row of the same table. So the ongoing cost is knowable on day one, and it never stops.
  • Audit time is never cut by more than 30%, whatever the discount is called. That ceiling is in the rule.
  • Your certification body cannot be your consultant. ISO/IEC 17021-1 clause 5.2.5, in terms. If one firm offers you both, something is wrong with one of the offers.
  • ISO/IEC 27001:2022 has 93 Annex A controls. Anything still saying 114 is describing the withdrawn ISO/IEC 27001:2013, whose certificates expired on 31 October 2025.

Three roles, and we are none of them

Most of the expensive mistakes in this market start with one misunderstanding: that the firm helping you prepare can also hand you the certificate. It cannot, and the reason is written into the standard that certification bodies are accredited against.

The three roles in ISO 27001 certification and the rule separating them Three boxes: UKAS accredits certification bodies; certification bodies audit and certify you; consultancies help you prepare. A crossed line between certification body and consultancy marks the bar in ISO/IEC 17021-1 clause 5.2.5. A footer notes that this site is none of the three. Accreditation body UKAS Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 Issues no certificates to you Certification body Audits you Runs Stage 1 and Stage 2 Issues your certificate Surveillance every year Cannot consult for you Consultancy Helps you get ready Gap analysis, risk assessment Statement of Applicability Internal audit support Cannot certify you accredits barred by 17021-1 cl. 5.2.5 iso27001partners.co.uk is none of these three. We publish the rules and the arithmetic, and sell advertising to consultancies at a fixed fee per enquiry. We cannot audit, certify or accredit anything.
The body that audits you is barred from selling you the help to get ready. That is a requirement of the standard its accreditation is granted against, not a market convention.
The same diagram as a table
Who does what, and what each one is barred from doing
RoleDoesCannot do
Accreditation body (UKAS)Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1Issue you a certificate
Certification bodyStage 1, Stage 2, annual surveillance, issues the certificateProvide management system consultancy to you (clause 5.2.5)
ConsultancyGap analysis, risk assessment, Statement of Applicability, internal audit supportIssue or influence a certificate
This sitePublishes the rules and the cost arithmetic; sells advertisingAudit, certify, accredit or advise

That separation is not a professional courtesy. ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 is the rule UKAS assesses certification bodies against, and clause 5.2.5 says plainly that the certification body “shall not offer or provide management system consultancy”. Clause 5.2.9 goes further and forbids a certification body from even implying that certification would be “simpler, easier, faster or less expensive” if you used a particular consultancy.

Knowing that changes what you ask for. You are buying two separate things from two separate suppliers, and the second one — the audit — has a price floor set by a published table. How to check a certification body covers what to look for.

We are paid a fixed fee per enquiry, agreed before anyone sends us one. It does not change with the size of your engagement, with which consultancy you pick, or with whether you certify at all. That is the only reason to believe the comparison tables on this site: there is no version of them that pays us more.

What it costs, and which half is actually knowable

Cost questions in this market get answered with a range so wide it is useless — one published UK guide puts implementation at anywhere from £500 to £40,000, an eighty-fold spread. Part of that is honest, because preparation genuinely varies. But it hides the fact that half of the total is set by a rule and can be stated precisely.

Where the money goes on an ISO 27001 certification Three horizontal ranges for a 25-person scope: the certification audit, consultant-led preparation, and the annual surveillance audit, with a combined three-year total underneath. Worked example: 25 people in scope, one site, no adjustments Certification audit 7 days, from the published table £7,700–£10,500 Preparation, consultant-led 10–22 consultant days £6,000–£26,400 Surveillance, per year 2.33 days, one third of the initial audit £2,550–£3,500 First three years, all in £18,800 to £43,900  ·  midpoint about £31,350 Certification audit + preparation + two surveillance years. Day counts exact; money estimated.
The audit is rarely the biggest number. Preparation is, and preparation is the part with no published rule behind it — which is exactly why every site in this market asks you to ring them about it.
The same diagram as a table
Cost parts for 25 people in scope, one site, no adjusting factors
PartLowHighBasis
Certification audit£7,700£10,5007 days, from the published table
Preparation, consultant-led£6,000£26,40010–22 consultant days
Surveillance, per year£2,550£3,5002.33 days, one third of the initial audit
First three years£18,800£43,900 Audit + preparation + two surveillance years

Day counts come from ISO/IEC 27006-1:2024 Table C.1 and are exact. The money is our estimate built on a day-rate band, rendered as a range and never as a single figure.

The certification audit is arithmetic: find your headcount band in the table, apply any adjustment for sites and complexity within the 30% ceiling the rule allows, multiply by a day rate. We can do the first two exactly and only have to estimate the third. Preparation is the opposite: no published rule, and it is usually the bigger number.

The full cost breakdown works through all four parts with the tables, or the calculator does it for your headcount in one screen.

What you are actually certified against

A surprising amount of published guidance treats ISO 27001 as a list of 93 security controls to implement. It is not. You are certified against clauses 4 to 10 — the management system itself. Annex A is a reference list you select from, and the selection has to be justified in a Statement of Applicability, including the controls you decided not to apply.

A cold aisle between two rows of closed server cabinets
You are certified against a management system, not against a server room. The infrastructure is evidence, not the subject.
Annex A controls by theme, 2022 edition against 2013 A proportional bar split into four themes totalling 93 controls in the 2022 edition, above a bar showing the 114 controls of the withdrawn 2013 edition for comparison. ISO/IEC 27001:2022 — Annex A: 93 controls, four themes Each block is drawn in proportion to the number of controls it holds. 37 Organisational A.5 8 People A.6 14 Physical A.7 34 Technological A.8 ISO/IEC 27001:2013 — Annex A: 114 controls, 14 clauses 114 controls, withdrawn — certificates against this edition expired on 31 October 2025 11 of the 93 are genuinely new. The rest are the 2013 controls merged and rewritten — the count fell because controls were combined, not because requirements were dropped.
Always ask which edition a control count belongs to. A document that says “114 controls” today was written before October 2022 and has not been revisited since.
The same diagram as a table
Annex A control counts, by edition
ThemeReferenceControlsCovers
OrganisationalA.537Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed.
PeopleA.68Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working.
PhysicalA.714Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring.
TechnologicalA.834Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about.
ISO/IEC 27001:2022 total93Four themes
ISO/IEC 27001:2013 total114 14 clauses, A.5 to A.18. Withdrawn.

That is why two organisations of the same size can have honestly different amounts of work in front of them, and why “how many controls have you got left” is the wrong question to ask a consultant. The controls, theme by theme sets out what is in each one and which are new since 2022.

Start where your question is

Common questions

How much does ISO 27001 certification cost in the UK?

It splits into two questions with very different answers. The certification audit itself is predictable: the number of days is set by Table C.1 of ISO/IEC 27006-1:2024, which every accredited certification body works to, and it runs from 5 days for 1 to 10 people up to 28 days for 8,501 to 10,700. At UK day rates that is roughly £7,700 to £10,500 for a 25-person scope. Getting ready is the part that varies, and it is usually the larger number: anywhere from the price of a document toolkit, if you have the people and the time, to £26,400 or more for a consultant-led build at that size. The day counts on this site are exact because they come from a published rule. Every pound figure is our estimate and is labelled as one.

Is iso27001partners.co.uk a certification body?

No, and that distinction matters more here than in most markets. There are three roles: UKAS accredits certification bodies; certification bodies audit you and issue certificates; consultancies help you get ready. We are none of them. We are an independent publisher. We explain what the standards require, publish the audit-day table in full, and run an enquiry form that goes to ISO 27001 consultancies. We cannot issue, arrange or influence a certificate, and nobody who is not accredited can.

Can my consultant also certify me?

No. ISO/IEC 17021-1 clause 5.2.5 says the certification body “shall not offer or provide management system consultancy”, and clause 5.2.7 adds that where a client has taken consultancy from a body related to a certification body, that body must not certify the management system for at least two years afterwards. So the firm that builds your ISMS cannot be the firm that audits it, and if the two are related you may have a two-year problem you did not know about. It is a fair question to ask both of them before you engage either.

What does it cost to use this site?

Nothing, and there is nothing to unlock. Every table, every figure and the calculator are on the page without a form in front of them. Consultancies pay a fixed advertising fee for each enquiry we pass on. That fee is agreed in advance and does not change with the size of the engagement, with whether you certify, or with anything a consultancy charges you.

How many controls does ISO 27001 have?

Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: organisational (37), people (8), physical (14), technological (34). The withdrawn ISO/IEC 27001:2013 had 114 in 14 clauses. Always check which edition a control count belongs to: a document that says 114 today was written before October 2022. You are certified against clauses 4 to 10, not against Annex A — Annex A is a reference set you select from and justify in a Statement of Applicability.

Do you recommend a particular consultancy?

No, and we are deliberate about that. We do not rank firms, score them or independently vet them. Your enquiry goes to consultancies advertising for your sector and you decide who, if anyone, you speak to. Because our fee is fixed per enquiry rather than taken from what a firm earns, we have nothing to gain from pointing you at one of them.

How long does ISO 27001 certification take?

The audit is the short part. Stage 1 and Stage 2 are separate visits with a gap between them for you to close anything Stage 1 found, and the certificate follows some weeks after the last audit day once the certification body's own review is done. Everything before that — scope, risk assessment, Statement of Applicability, the documented information, an internal audit under clause 9.2 and a management review under clause 9.3 — has no fixed length. Clause 9.2 and 9.3 are the constraint people miss: you cannot sit Stage 2 without having genuinely run both at least once, and that puts a floor under the timeline no amount of budget removes.

Does a certificate from a non-UKAS body count?

It depends entirely on who is asking, and you should find out before you buy one. An accredited certificate comes from a body UKAS has itself assessed against ISO/IEC 17021-1 and ISO/IEC 27006-1, and it carries the UKAS symbol and a published schedule of accreditation naming the scope. A non-accredited certificate is issued by a body nobody has assessed. Both are pieces of paper; only one has anyone standing behind it. Many procurement teams and most public-sector frameworks specify accredited certification explicitly, and a cheaper unaccredited certificate that then fails a customer's check has cost you the whole fee and the time.

Sources cited on this page

  1. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  2. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  3. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  4. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  5. The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
  6. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get a costed answer, not a call-back to discuss pricing

Five questions, all of them click-only. Your details are the last step, never the first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now